PT-2021-3971 · Interniche · Nichestack Tcp/Ip

Published

2021-05-28

·

Updated

2021-08-26

·

CVE-2020-25927

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions NicheStack TCP/IP version 4.0.1
Description The issue is related to errors in processing input data length parameters in the DNS client of NicheLite and InterNiche stacks. This can allow a remote attacker to cause a denial of service. The problem lies in the DNS response processing, specifically in the dns upcall() function, where the code fails to check if the number of queries or responses specified in the DNS packet header matches the available data in the packet. The attack vector involves a specific DNS response packet.
Recommendations For version 4.0.1, consider disabling the DNS feature or restricting access to the dns upcall() function until a patch is available to prevent exploitation. Additionally, avoid using the DNS response processing component until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04490
CVE-2020-25927

Affected Products

Nichestack Tcp/Ip